Data security in a mobile e-mail service
Summary by NHIP
Mobile Email Encryption Method
The method conveys email traffic by establishing an encrypted data channel between a server and a mobile terminal. A service activation code containing a terminal identifier and encryption information authenticates the user and configures the connectivity application to secure the channel.
Claim Score by NHIP
Abstract
A method for conveying e-mail traffic between an e-mail server (108) and a mobile terminal (102) which has an e-mail address (122A) under the e-mail server and permanent terminal identity (122B) and a temporary identity (122D) in an access network (114). A connectivity function (600) is operationally coupled to the e-mail server (108) and the access network (114). The connectivity function (120) encrypts e-mail traffic to the mobile terminal and decrypt e-mail traffic from the mobile terminal, by using encryption information (122C). The mobile terminal generates (2-1) a service activation code which comprises an identifier (124D) of the mobile terminal, encryption information (122C) and checksum information. The service activation code is conveyed (2-3, 2-4) via a secure channel (2-3) to an authenticating terminal (100), from which the identifier (124D) of the mobile terminal and the encryption information (122C) are conveyed to the connectivity function (600).

Term
Projected expiry 10 October 2027.
- Priority
- Filed
- Granted
- Today
- Projected expiry
10 claims: 2 independent, 8 dependent
- 1Broadest claimClaim Score 48, average(NHIP)A method for conveying e-mail traffic between an e-mail server and a mobile terminal, the method comprising:generating a service activation code at the mobile terminal, wherein the service activation code comprises an identifier of the mobile terminal and encryption information;providing the service activation code for authentication of a user of the mobile terminal, wherein the service activation code is provided at the mobile terminal;providing the identifier of the mobile terminal and the encryption information to a connectivity application at the e-mail server, wherein execution of the connectivity application at the e-mail server in response to receipt of the identifier and encryption information establishes an encrypted data channel using the provided encryption information;and connecting to the established encrypted data channel for conveyance of e-mail traffic, wherein the mobile terminal has an e-mail address under the e-mail server, a permanent terminal identity assigned to the mobile terminal, and a temporary identity in an access network, the temporary identity based on an identifier of the tunnel to the mobile terminal.
- 10A computer-readable storage medium having embodied thereon a program, the program being executable by a computing device to perform a method for conveying e-mail traffic between an e-mail server and a mobile terminal, the method comprising:generating a service activation code at the mobile terminal, wherein the service activation code comprises an identifier of the mobile terminal and encryption information;providing the service activation code for authentication of a user of the mobile terminal, wherein the service activation code is provided at the mobile terminal;providing the identifier of the mobile terminal and the encryption information to a connectivity application at the e-mail server, wherein execution of the connectivity application at the e-mail server in response to receipt of the identifier and encryption information establishes an encrypted data channel using the provided encryption information;and connecting to the established encrypted data channel for conveyance of e-mail traffic, wherein the mobile terminal has an e-mail address under the e-mail server, a permanent terminal identity assigned to the mobile terminal, and a temporary identity in an access network, the temporary identity based on an identifier of the tunnel to the mobile terminal.
Independent claims2
27 paragraphs in 5 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
This application relies for priority upon Finnish Application No. 20045451, filed Nov. 22, 2004, and Finnish Application No. 20055038, filed Jan. 26, 2005, as well as U.S. Provisional Application Nos. 60/650,975 and 60/151,082, both filed Feb. 9, 2005, the contents of all of which are incorporated herein by reference in their entireties.
BACKGROUND OF THE INVENTION
The invention relates to methods and equipment for establishing data security in an e-mail service between an e-mail server and a mobile terminal.
Data security in an e-mail service is achieved by using cryptographic techniques in which traffic in a potentially insecure channel is encrypted using cryptographic information, commonly called encryption keys. A problem underlying the invention relates to distributing such encryption information. Prior art techniques for distributing the encryption information are commonly based on public key encryption techniques, such as Diffie-Hellman. A problem with this approach is that the parties have to trust the underlying mobile network and its operator, which they are surprisingly reluctant to do. Another problem is that mobile terminals tend to have small and restricted user interfaces.
BRIEF DESCRIPTION OF THE INVENTION
An object of the present invention is to provide a method and an apparatus for implementing the method so as to alleviate the above problems. The object of the invention is achieved by the methods and equipment which are characterized by what is stated in the independent claims. Preferred embodiments of the invention are disclosed in the dependent claims.
The invention is partially based on the discovery of a surprising problem that has been found as a result of extensive market research. Although clients of mobile networks normally trust their mobile operators as regards voice calls, they are surprisingly reluctant to trust the mobile operators as regards data services, such as e-mail service. The reluctance to trust mobile operators in respect of data services makes public-key interchange schemes unattractive.
An aspect of the invention is a method for conveying e-mail traffic between an e-mail server and a mobile terminal, wherein the mobile terminal has an e-mail address under the e-mail server, and permanent terminal identity and a temporary identity in an access network. The method comprises the following steps: <ul><li id="ul0001-0001" num="0000"><ul><li id="ul0002-0001" num="0007">A connectivity function, which acts as a mediator between the e-mail server and the mobile terminal, is operationally coupled to the e-mail server and the access network. The connectivity function is configured to encrypt e-mail traffic to the mobile terminal and decrypt e-mail traffic from the mobile terminal. In order to encrypt and decrypt e-mail traffic, the connectivity function needs encryption information.</li><li id="ul0002-0002" num="0008">The required encryption information is generated at the mobile terminal.</li><li id="ul0002-0003" num="0009">The generated encryption information and an identifier of the mobile terminal are conveyed via a secure channel to the connectivity function, after authenticating the entity that conveys the encryption information or by utilizing an already-performed authentication of the entity.</li></ul></li></ul>
The encryption information and the identifier of the mobile terminal are combined into a service activation code, which also includes checksum information so as to detect an incorrectly entered service activation code.
In an embodiment of the invention, the secure channel for conveying the encryption information is implemented as follows. The user of the mobile terminal may have a host system, such as an office terminal, which is coupled to the connectivity function via a private network. The private network requires authentication in order to grant access to users. In this embodiment the mobile terminal generates the encryption information and displays it on its display, and the user enters the encryption information to the host system that is coupled to the private network.
Alternatively, the mobile terminal user may have a trust relation with another person, such as a support technician, who is authenticated in the private network. For example, trust relation may be established in a voice call in which the support technician recognizes the voice of the mobile terminal user. The mobile terminal user then dictates the encryption information to the support technician who enters it via a host system coupled to the private network.
Thus the secure channel from the mobile terminal to the connectivity function comprises a short segment over which the encryption information is conveyed off-line to a human user that may be the user of the mobile terminal or someone Who trusts him/her. The off-line segment is a segment that is detached from public networks and is immune against hacking or eavesdropping via public networks. The off-line segment may be implemented visually, such that the mobile terminal displays the encryption information on its display, and the user enters it into a terminal of the private network. Alternatively, the encryption information may be conveyed on a detachable memory or via a short-range microwave connection, an example of which is known as Bluetooth. The secure channel also comprises a segment spanned by the private network. The secure channel may also comprise a segment spanned by a conventional voice call, if the mobile terminal user is distant from a terminal of the private network.
BRIEF DESCRIPTION OF THE DRAWINGS
In the following the invention will be described in greater detail by means of preferred embodiments with reference to the attached drawings, in which
<figref idrefs="DRAWINGS">FIG. 1</figref> shows an exemplary system architecture in which the invention can be used;
<figref idrefs="DRAWINGS">FIG. 2</figref> shows procedure steps for establishing a secure connection.
DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS
The invention is applicable to virtually any mobile e-mail system architecture. <figref idrefs="DRAWINGS">FIG. 1</figref> shows an exemplary system architecture which is supported by the owner of the present application. Reference numeral <b>100</b> denotes a host system that is able to send an receive e-mail messages. Reference numeral <b>102</b> denotes a mobile terminal, also able to send an receive e-mail messages. The e-mail messages may originate or terminate at external e-mail terminals, one of which is denoted by reference numeral <b>104</b>. The invention aims at improving cooperation between the host system <b>100</b> and mobile terminal <b>102</b> such that they can use a single e-mail account as transparently as possible. This means, for example, that the users of the external e-mail terminals <b>104</b>, when sending or receiving e-mail, do not need to know if the user of the host system <b>100</b> actually uses the host system <b>100</b> or the mobile terminal <b>102</b> to communicate via e-mail. The transparency also means that e-mail manipulation at the mobile terminal <b>102</b> has, as far as possible, the same effect as the corresponding e-mail manipulation at the host system <b>100</b>. For example, e-mail messages read at the mobile terminal <b>102</b> should preferably be marked as read at the host system.
Reference numeral <b>106</b> denotes a data network, such as an IP (Internet Protocol) network, which may be the common Internet or its closed subnetworks, commonly called intranets or extranets. Reference numeral <b>108</b> denotes an e-mail server and its associated database. There may be separate e-mail servers and/or server addresses for incoming and outgoing e-mail. The database stores an e-mail account, addressable by means of an e-mail address, that appears as a mailbox to the owner of the e-mail account. In order to communicate with mobile terminals <b>102</b>, the data network <b>106</b> is connected, via a gateway <b>112</b> to an access network <b>114</b>. The access network comprises a set of base stations <b>116</b> to provide wireless coverage over a wireless interface <b>118</b> to the mobile terminals <b>102</b>.
Reference numeral <b>110</b> denotes a messaging centre that is largely responsible for providing the above-mentioned transparency between the host system <b>100</b> and the mobile terminal <b>102</b>. The system architecture also comprises a connectivity function <b>120</b>, whose task is to push e-mail messages to the mobile terminal. In the embodiment shown in <figref idrefs="DRAWINGS">FIG. 1</figref>, the connectivity function <b>120</b> is considered a physically integral but logically distinct element of the messaging centre <b>110</b>.
The mobile terminal <b>102</b> may be a pocket or laptop computer with a radio interface, a smart cellular telephone, or the like. Depending on implementation, the host system <b>100</b>, if present, may have different roles. In some implementations the host system <b>100</b> is optional and may be a conventional office computer that merely acts as the mobile terminal user's principal computer and e-mail terminal. In other implementations the host system may act as a platform for a single user's connectivity function, in addition to being an office computer. In yet other implementations the host system <b>100</b> may comprise the connectivity function for several users. Thus it is a server instead of a normal office computer.
We assume here that the access network <b>114</b> is able to establish and maintain a tunnel <b>122</b> between the messaging centre <b>110</b> and the mobile terminal <b>102</b>. For instance, the tunnel may be set up using GPRS Tunnelling Protocol (GTP) or its later derivatives, or any other suitable tunnelling protocol.
<figref idrefs="DRAWINGS">FIG. 1</figref> shows an embodiment in which the messaging centre <b>110</b> is largely responsible for e-mail transport to/from the mobile terminal <b>102</b> via the access network <b>114</b>, while a separate connectivity function <b>120</b> is responsible for data security issues. The connectivity function <b>120</b> may be physically attached to or co-located with the messaging centre <b>110</b>, but they are logically separate elements. Indeed, a definite advantage of the separate connectivity function <b>120</b> is that it can be detached from the messaging centre, for instance, within the company that owns the host system <b>100</b> or the e-mail server <b>108</b>. For a small number of users, the connectivity function <b>120</b> can be installed in each host system <b>100</b>, or the host system <b>100</b> can be interpreted as a separate server configured to support multiple users. It is even possible to implement some or all the above-mentioned options. This means, for example, that there is one or more messaging centres <b>110</b> that offer services to several network operators, or they may be a dedicated messaging centre for each network operator (somewhat analogous to short messaging centres). Each messaging centre <b>110</b> may have an integral connectivity function <b>120</b> to support users who don't wish to install a separate connectivity function in a host system <b>100</b>. For users who do install a separate connectivity function <b>120</b> in their host systems <b>100</b>, such connectivity functions bypass the connectivity function in the messaging centre <b>110</b> and address the messaging centre <b>110</b> directly.
A real e-mail system supports a large number of mobile terminals <b>102</b> and tunnels <b>122</b>. In order to keep track of which e-mail account and which tunnel belongs to which mobile terminal, the messaging centre <b>110</b> and the connectivity function collectively maintain an association <b>124</b>, <b>124</b>′ for each supported mobile terminal. Basically, each association <b>124</b>, <b>124</b>′ joins three fields, namely an e-mail address <b>124</b>A assigned to the mobile terminal or its user, encryption information <b>124</b>C and a temporary wireless identity <b>124</b>D of the mobile terminal in the access network. The embodiment shown in <figref idrefs="DRAWINGS">FIG. 1</figref> also employs a terminal identifier <b>124</b>B which may be the same as the e-mail address <b>124</b>A of the mobile terminal <b>102</b>, in which case the association <b>124</b> actually associates three information items. Alternatively, the terminal identifier <b>124</b>B may be an identifier arbitrarily assigned to the mobile terminal. In a preferred implementation the terminal identifier <b>124</b>B is the mobile terminal's equipment identifier or its derivative. The encryption information <b>124</b>C is preferably related to the mobile terminal's equipment identity and is preferably generated by the mobile terminal itself, so as to ensure that no other terminal besides the one used for creating the encryption information <b>124</b>C will be able to decrypt incoming encrypted e-mail messages. The temporary wireless identity <b>124</b>D may be the identifier of the tunnel <b>122</b> to the mobile station. Of course, the tunnel identifier is not permanent and is only known when a tunnel exists.
<figref idrefs="DRAWINGS">FIG. 2</figref> shows a secure e-mail provisioning technique in which the host system <b>100</b> authenticates the user of the mobile terminal <b>102</b>. In step <b>2</b>-<b>1</b> the client software in the mobile terminal <b>102</b> generates and displays a service activation code. In step <b>2</b>-<b>2</b> the host system <b>100</b> authenticates the person who enters the service activation code. Instead of a dedicated authentication step, the technique may rely on the authentication of the underlying e-mail system, such as user name and password combination. After all, the e-mail provisioning need not be more secure than the underlying e-mail system. In step <b>2</b>-<b>3</b> the service activation code is then conveyed off-line to the host system <b>100</b>. The idea of the off-line communication is to eliminate any chance of eavesdropping before secure a communication channel can be established. For instance, the service activation code may be entered manually or via a local connection, such as a wired or optical interface or a short-range wireless interface, such as Bluetooth™. Finally, in step <b>2</b>-<b>4</b>, the mobile terminal's service activation code is registered with the connectivity function <b>120</b>.
The service activation code is closely related to an encryption key to be used in future communications between the connectivity function <b>120</b> and the mobile terminal <b>102</b>. The service activation code and the encryption key may be identical, or one may be a subset of the other, or the encryption key may be derived from the service activation code by means of some, preferably unpublished, algorithm. The fact that the service activation code and the encryption key are closely related to each other ensures that the terminal used in the authentication process is the terminal used to access the e-mail service afterwards.
Thus the idea of conveying the service activation code to the connectivity function <b>120</b> via the host system <b>100</b> solves both the security-related and user interface-related problems mentioned above. If there is no host system <b>100</b> that can authenticate the mobile terminal and its user. Instead, the user may enter the provisioning data to the connectivity function via some suitable connection. The provisioning data entered by the user may be checked by sending a trial e-mail message and attempting to read it. If the check succeeds, it is regarded as the authentication. Yet another way is to convey the service activation code to a dedicated support person who performs the authentication (eg by recognizing the person's face or voice) and enters the service activation code into the connectivity function <b>120</b>. The connectivity function <b>120</b> now stores an association (item <b>124</b> in <figref idrefs="DRAWINGS">FIG. 1</figref>) between the e-mail address <b>124</b>A and encryption information <b>124</b>C.
The mobile terminal preferably generates the service activation code based on the encryption key, the mobile terminal's identifier and a checksum. A benefit of the checksum is that invalid service activation codes can be detected, considering the fact that the service activation code may be conveyed via channels that are immune to electrical eavesdropping but very prone to human errors. For example, the service activation code may be read visually from the mobile terminal's display and entered manually into another terminal.
The mobile terminal's identifier can be its IMEI, IMSI, MSISDN, or other network identifier. A benefit of encoding the mobile terminal's identifier and the encryption key into the service activation key is that the connectivity function <b>120</b> needs both to communicate with the mobile terminal. The connectivity function <b>120</b> needs the mobile terminal's identifier in order to send data to the mobile terminal. The connectivity function <b>120</b> also needs the encryption key because it is the mobile terminal's peer entity as regards encryption. As soon as the connectivity function <b>120</b> receives knowledge of the mobile terminal's identifier and the encryption key, it can send the mobile terminal a first message comprising service provisioning settings, after which it can begin sending user traffic, such as new e-mail messages, calendar information and the like.
As stated in the description of <figref idrefs="DRAWINGS">FIG. 1</figref>, there are several possible implementations for the connectivity function <b>120</b>. For example, it can be installed in a public data network, such as the Internet, as a physically integral element of the messaging centre <b>110</b> but logically distinct from it. It can also be installed in a company's private network within a firewall. It can be installed as a process in each mobile terminal user's office computer, or one common server can support all mobile users of the company, somewhat analogously to a company's e-mail server. The advantages of the invention are easiest to see when the connectivity function is dedicated to a particular company and is located within the company's firewall. This is because in this implementation there are several connectivity functions, and the mobile terminal has no a priori knowledge of which one it should connect to. A coarse solution to this problem is requesting this information from the user, but entering exact configuration information via a small user interface is one of the problems this invention attempts to solve.
It is readily apparent to a person skilled in the art that, as the technology advances, the inventive concept can be implemented in various ways. The invention and its embodiments are not limited to the examples described above but may vary within the scope of the claims.
Contents5
2 sheets
Sheet 1 Sheet 2
Every citation, both waysCites: the store holds 77 of 78
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2009054034A1 | Cited by | United States of America | Pre-grant |
| US10659421B2 | Cited by | United States of America | Applicant |
| US10263899B2 | Cited by | United States of America | Applicant |
| US8805334B2 | Cited by | United States of America | Search report |
| US9712986B2 | Cited by | United States of America | Applicant |
| US9832095B2 | Cited by | United States of America | Applicant |
| US10856355B2 | Cited by | United States of America | Applicant |
| WO03007570A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO03098890A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO03098890A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| EP0772327A2 | Cites | European Patent Office (EPO) | Applicant |
| US2002019225A1 | Cites | United States of America | Applicant |
| WO2004045171A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO2004045171A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| US2004205330A1 | Cites | United States of America | Applicant |
| US2006265595A1 | Cites | United States of America | Search report |
| US4831582A | Cites | United States of America | Applicant |
| US4875159A | Cites | United States of America | Applicant |
| US4897781A | Cites | United States of America | Applicant |
| US5263157A | Cites | United States of America | Applicant |
| US5386564A | Cites | United States of America | Applicant |
| US5392390A | Cites | United States of America | Applicant |
| US5572643A | Cites | United States of America | Applicant |
| US5581749A | Cites | United States of America | Applicant |
| US5600834A | Cites | United States of America | Applicant |
| US5613012A | Cites | United States of America | Applicant |
| US5623601A | Cites | United States of America | Applicant |
| US5627658A | Cites | United States of America | Applicant |
| US5630081A | Cites | United States of America | Applicant |
| US5634053A | Cites | United States of America | Applicant |
| US5647002A | Cites | United States of America | Applicant |
| US5652884A | Cites | United States of America | Applicant |
| US5666553A | Cites | United States of America | Applicant |
| US5680542A | Cites | United States of America | Applicant |
| US5682524A | Cites | United States of America | Applicant |
| US5684990A | Cites | United States of America | Applicant |
| US5701423A | Cites | United States of America | Applicant |
| US5704029A | Cites | United States of America | Applicant |
| US5706502A | Cites | United States of America | Applicant |
| US5710918A | Cites | United States of America | Applicant |
| US5713019A | Cites | United States of America | Applicant |
| US5715403A | Cites | United States of America | Applicant |
| US5717925A | Cites | United States of America | Applicant |
| US5721908A | Cites | United States of America | Applicant |
| US5721914A | Cites | United States of America | Applicant |
| US5727202A | Cites | United States of America | Applicant |
| US5729735A | Cites | United States of America | Applicant |
| US5745360A | Cites | United States of America | Applicant |
| US5752246A | Cites | United States of America | Applicant |
| US5757916A | Cites | United States of America | Applicant |
| US5758150A | Cites | United States of America | Applicant |
| US5758354A | Cites | United States of America | Applicant |
| US5758355A | Cites | United States of America | Applicant |
| US5765171A | Cites | United States of America | Applicant |
| US5778346A | Cites | United States of America | Applicant |
| US5787441A | Cites | United States of America | Applicant |
| US5790425A | Cites | United States of America | Applicant |
| US5790790A | Cites | United States of America | Applicant |
| US5799318A | Cites | United States of America | Applicant |
| US5832483A | Cites | United States of America | Applicant |
| US5857201A | Cites | United States of America | Applicant |
| US5870759A | Cites | United States of America | Applicant |
| US5909689A | Cites | United States of America | Applicant |
| US5943676A | Cites | United States of America | Applicant |
| US5968131A | Cites | United States of America | Applicant |
| US6006274A | Cites | United States of America | Applicant |
| US6023708A | Cites | United States of America | Applicant |
| US6044381A | Cites | United States of America | Applicant |
| US6085192A | Cites | United States of America | Applicant |
| US6131096A | Cites | United States of America | Applicant |
| US6131116A | Cites | United States of America | Applicant |
| US6138124A | Cites | United States of America | Applicant |
| US6141664A | Cites | United States of America | Applicant |
| US6151606A | Cites | United States of America | Applicant |
| US6212529B1 | Cites | United States of America | Applicant |
| US6219694B1 | Cites | United States of America | Applicant |
| US6223187B1 | Cites | United States of America | Applicant |
| US6233341B1 | Cites | United States of America | Applicant |
| US6324542B1 | Cites | United States of America | Applicant |
| US6708221B1 | Cites | United States of America | Applicant |
| US6732101B1 | Cites | United States of America | Applicant |
| US6745326B1 | Cites | United States of America | Applicant |
| US6799190B1 | Cites | United States of America | Applicant |
| WO9824257A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| Lotus Development Corporation, Lotus Quick Reference for SmartIcons, Lotus Notes Release 3.1. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Quick Reference for Windows and Presentation Manager, Lotus Notes Release 3. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Quick Reference for Macintosh, Lotus Notes Release 3.0. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Quick Reference for Application Developer's, Lotus Notes Release 3. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Customer Support Service, Lotus Notes Customer Support Guides. | Non-patent | – | Applicant |
| Lotus Software Agreement for "Notes 4.0 NA DKTP Client UPG", Part No. 38985. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Notes 3.3, Lotus Customer Support, North American Guide, 29 pages. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Notes 4.0, Lotus Customer Support, North American Guide, 29 pages. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Notes 4.1 Starter Pack, Lotus Customer Support, North American Guide, 51pages. | Non-patent | – | Applicant |
| Lotus Development Corporation, "Lotus Script Classes for Notes Release 4",6 pages. | Non-patent | – | Applicant |
| Allchin, James E., "An Architecture for Reliable Decentralized Systems", UMI Dissertation Services, Copyright 1983. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Notes Release 3.1. The Groupware Standard, Administrator's Guide-Server for NetWare, OS/2, and UNIX,1989. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Notes Release 3.1: The Groupware Standard, Site and Systems Planning Guide, 1991. | Non-patent | – | Applicant |
| Wilcox, Adam A., PC Learning Labs Teaches Lotus Notes 3.0: The Quick and Easy Way to Learn, Ziff-Davis Press, 1993. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Notes Release 3.3: Start Here, Workstation Install for Windows, OS/2 and Macintosh, 1993. | Non-patent | – | Applicant |
| Lotus Development Corporation, Lotus Notes Release 3.1: Administrator's Guide-Server for Windows, 1993. | Non-patent | – | Applicant |
35 members in 4 offices
Priority claims18
| Document | Office | Kind | Date |
|---|---|---|---|
| 20045451 | Finland | A | |
| 20045451 | Finland | A | |
| 20055038 | Finland | A | |
| 20055038 | Finland | A | |
| 65097505 | United States of America | P | |
| 65097505 | United States of America | P | |
| 65108205 | United States of America | P | |
| 65108205 | United States of America | P | |
| 28260705 | United States of America | A | |
| 20045451 | – | – | – |
| 20055038 | – | – | – |
| 60650975 | – | – | – |
| 60651082 | – | – | – |
| FI20040005451 | – | – | – |
| FI20050005038 | – | – | – |
| US20050282607 | – | – | – |
| US20050650975P | – | – | – |
| US20050651082P | – | – | – |
Members35
| Document | Office | Kind | |
|---|---|---|---|
| US840000A | United States of America | A | |
| US843107A | United States of America | A | |
| FI20045451A0 | Finland | A0 | |
| FI20055038A0 | Finland | A0 | |
| FI20045451A | Finland | A | |
| FI20045451L | Finland | L | |
| WO2006053952A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO2006053954A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FI20055038A | Finland | A | |
| FI20055038L | Finland | L | |
| US2006240804A1 | United States of America | A1 | |
| US2006240805A1 | United States of America | A1 | |
| EP1815634A1 | European Patent Office (EPO) | A1 | |
| EP1815652A1 | European Patent Office (EPO) | A1 | |
| FI118288B | Finland | B | |
| FI119581B | Finland | B | |
| US2009054034A1 | United States of America | A1 | |
| US2009063647A1 | United States of America | A1 | |
| US2009075683A1 | United States of America | A1 | |
| US7643818B2 | United States of America | B2 | |
| US7706781B2This record | United States of America | B2 | |
| US7769400B2 | United States of America | B2 | |
| EP1815634A4 | European Patent Office (EPO) | A4 | |
| EP1815652A4 | European Patent Office (EPO) | A4 | |
| US8805334B2 | United States of America | B2 | |
| EP1815634B1 | European Patent Office (EPO) | B1 | |
| US2015149575A1 | United States of America | A1 | |
| EP1815652B1 | European Patent Office (EPO) | B1 | |
| US10027619B2 | United States of America | B2 | |
| US2018343226A1 | United States of America | A1 | |
| US10659421B2 | United States of America | B2 | |
| US2020296072A1 | United States of America | A1 | |
| US11290416B2 | United States of America | B2 | |
| US2022210112A1 | United States of America | A1 | |
| US12316598B2 | United States of America | B2 |
80 transactions on the USPTO file
Allowed after 2 non-final rejections, 1 final rejection and 1 appeal.
- Non-final rejections
- 2
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 12th Year, Large EntityM1553 | M1553 | |
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Mail Appeals conf. Reopen Prosec.MAPCR | MAPCR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Pre-Appeals Conference Decision - Reopen ProsecutionAPCR | APCR | |
| Request for Pre-Appeal Conference FiledAP.C | AP.C | |
| Notice of Appeal FiledN/AP | N/AP | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response to Election / Restriction FiledELC. | ELC. | |
| Mail Restriction RequirementMCTRS | MCTRS | |
| Restriction/Election RequirementCTRS | CTRS | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Application Is Now CompleteCOMP | COMP | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Request for Foreign Priority (Priority Papers May Be Included)RQPR | RQPR | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Additional Application Filing FeesADDFLFEE | ADDFLFEE | |
| A statement by one or more inventors satisfying the requirement under 35 USC 115, Oath of the ApplicOATHDECL | OATHDECL | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Cleared by L&R (LARS)L128 | L128 | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Preliminary AmendmentA.PE | A.PE | |
| Initial Exam Team nnIEXX | IEXX |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedurePAT HOLDER NO LONGER CLAIMS SMALL ENTITY STATUS, ENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: STOL); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| Fee paymentFPAY | FPAY | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 07706781
- Publication, DOCDB
- 7706781
- Publication, EPODOC
- US7706781
- Application
- 11282607
- Application, DOCDB
- 28260705
- Application, EPODOC
- US20050282607
Titles
- English
- Data security in a mobile e-mail service
Patent term adjustment
- A delay
- +385 daysthe office missed an examination deadline
- B delay
- +395 dayspendency past three years
- Overlap
- −5 daysdelays counted once
- Applicant delay
- −87 days
- Net adjustment
- 688 days
Classification
- CPC, 8
- H04L63/0428
- H04W12/02
- H04L63/08
- H04L63/18
- H04W4/12
- H04W12/06
- H04W12/033
- H04L51/58
- IPC, 2
- H04M11 10
- H04W4 12
- USPC, 4
- 455413000
- 455412100
- 455414100
- 455414400